[NT] Sambar Telnet Proxy Multiple Vulnerabilities (DoS, Buffer Overflow)
From: support@securiteam.comDate: 08/14/01
- Previous message: support@securiteam.com: "[NEWS] Abusing Poor Programming Techniques in Web Server Scripts (SQL Statements)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Subject: [NT] Sambar Telnet Proxy Multiple Vulnerabilities (DoS, Buffer Overflow) Message-Id: <20010814063009.BC4DA138BF@mail.der-keiler.de> Date: Tue, 14 Aug 2001 08:30:09 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
Sambar Telnet Proxy Multiple Vulnerabilities (DoS, Buffer Overflow)
------------------------------------------------------------------------
SUMMARY
The <http://www.Sambar.com/> Sambar Server was created to test a
three-tier communication infrastructure modeled after the Sybase Open
Client/Open Server. Soon thereafter, the idea of leveraging the
infrastructure for dynamic delivery of content on the WWW resulted in the
addition of an HTTP protocol stack, and efforts in supporting the notion
of persistent users via HTTP. Multiple security vulnerabilities have been
found in the product. Those allow attackers to cause the server to crash,
and to execute arbitrary code.
DETAILS
Denial of service attack:
The Sambar Telnet Proxy allows attackers to connect to the localhost,
continuesly connecting to the localhost will cause the server to stop
responding after about 40 such connections.
Buffer overflow in telnet proxy/server:
Sending a host name of more than 1100 characters causes the server to
overflow one of its internal buffers, causing it to crash and execute
arbitrary code.
ADDITIONAL INFORMATION
The information has been provided by <mailto:kyprizel@mail.kz> kyprizel.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NEWS] Abusing Poor Programming Techniques in Web Server Scripts (SQL Statements)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|